Stack-based buffer overflow in corosync - CVE-2025-30472
Published: March 26, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in orf_token_endian_convert() function in exec/totemsrp.c. A remote attacker can send an overly large UDP packet to the application, trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability requires that encryption is disabled.
Affected software
SUSE Enterprise Server 15 SP3 Business Critical
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Availability Extension 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
Anolis OS
Fedora
openSUSE Leap
openEuler
Ubuntu
Watson Query on Cloud Pak for Data
Data Virtualization (DV) on Cloud Pak for Data (CPD)
Db2 Big SQL
IBM OpenPages with Watson
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Security Verify Governance
libcorosync_common4-32bit
libcmap4-32bit-debuginfo
libsam4-32bit
libcpg4-32bit
libvotequorum8-32bit
libquorum5-32bit-debuginfo
libcfg6-32bit-debuginfo
libcpg4-32bit-debuginfo
libsam4-32bit-debuginfo
libvotequorum8-32bit-debuginfo
libtotem_pg5-32bit-debuginfo
libquorum5-32bit
libcfg6-32bit
libtotem_pg5-32bit
libcorosync_common4-32bit-debuginfo
libcmap4-32bit
libvotequorum8-64bit-debuginfo
libcmap4-64bit
libcorosync_common4-64bit-debuginfo
libcmap4-64bit-debuginfo
libsam4-64bit
libcfg6-64bit
libcpg4-64bit
libvotequorum8-64bit
libquorum5-64bit
libsam4-64bit-debuginfo
libtotem_pg5-64bit
libcfg6-64bit-debuginfo
libtotem_pg5-64bit-debuginfo
libcpg4-64bit-debuginfo
libquorum5-debuginfo
libcorosync_common4-64bit
libquorum5-64bit-debuginfo
libcfg6
libcmap4-debuginfo
corosync-testagents-debuginfo
corosync-debugsource
libcorosync-devel
libsam4
libvotequorum8-debuginfo
corosync
corosync-debuginfo
corosync-qdevice-debuginfo
corosync-qnetd-debuginfo
libquorum5
libtotem_pg5
libtotem_pg5-debuginfo
libcorosync_common4
corosync-qdevice
libsam4-debuginfo
libcpg4-debuginfo
libvotequorum8
corosync-testagents
libcfg6-debuginfo
libcorosync_common4-debuginfo
libcpg4
corosync-qnetd
libcmap4
corosync (Ubuntu package)
corosync-vqsim
corosynclib
corosynclib-devel
corosync-epel
How to mitigate CVE-2025-30472
Db2 Big SQL - update to 8.1
IBM OpenPages with Watson - update to 9.1.2
libcorosync_common4-32bit - update to 2.4.6-150300.12.13.1
libcmap4-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libsam4-32bit - update to 2.4.6-150300.12.13.1
libcpg4-32bit - update to 2.4.6-150300.12.13.1
libvotequorum8-32bit - update to 2.4.6-150300.12.13.1
libquorum5-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libcfg6-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libcpg4-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libsam4-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libvotequorum8-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libtotem_pg5-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libquorum5-32bit - update to 2.4.6-150300.12.13.1
libcfg6-32bit - update to 2.4.6-150300.12.13.1
libtotem_pg5-32bit - update to 2.4.6-150300.12.13.1
libcorosync_common4-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libcmap4-32bit - update to 2.4.6-150300.12.13.1
libvotequorum8-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libcmap4-64bit - update to 2.4.6-150300.12.13.1
libcorosync_common4-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libcmap4-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libsam4-64bit - update to 2.4.6-150300.12.13.1
libcfg6-64bit - update to 2.4.6-150300.12.13.1
libcpg4-64bit - update to 2.4.6-150300.12.13.1
libvotequorum8-64bit - update to 2.4.6-150300.12.13.1
libquorum5-64bit - update to 2.4.6-150300.12.13.1
libsam4-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libtotem_pg5-64bit - update to 2.4.6-150300.12.13.1
libcfg6-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libtotem_pg5-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libcpg4-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libquorum5-debuginfo - update to 2.4.6-150300.12.13.1
libcorosync_common4-64bit - update to 2.4.6-150300.12.13.1
libquorum5-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libcfg6 - update to 2.4.6-150300.12.13.1
libcmap4-debuginfo - update to 2.4.6-150300.12.13.1
corosync-testagents-debuginfo - update to 2.4.6-150300.12.13.1
corosync-debugsource - update to 2.4.6-150300.12.13.1
libcorosync-devel - update to 2.4.6-150300.12.13.1
libsam4 - update to 2.4.6-150300.12.13.1
libvotequorum8-debuginfo - update to 2.4.6-150300.12.13.1
corosync - update to 2.4.6-150300.12.13.1
corosync-debuginfo - update to 2.4.6-150300.12.13.1
corosync-qdevice-debuginfo - update to 2.4.6-150300.12.13.1
corosync-qnetd-debuginfo - update to 2.4.6-150300.12.13.1
libquorum5 - update to 2.4.6-150300.12.13.1
libtotem_pg5 - update to 2.4.6-150300.12.13.1
libtotem_pg5-debuginfo - update to 2.4.6-150300.12.13.1
libcorosync_common4 - update to 2.4.6-150300.12.13.1
corosync-qdevice - update to 2.4.6-150300.12.13.1
libsam4-debuginfo - update to 2.4.6-150300.12.13.1
libcpg4-debuginfo - update to 2.4.6-150300.12.13.1
libvotequorum8 - update to 2.4.6-150300.12.13.1
corosync-testagents - update to 2.4.6-150300.12.13.1
libcfg6-debuginfo - update to 2.4.6-150300.12.13.1
libcorosync_common4-debuginfo - update to 2.4.6-150300.12.13.1
libcpg4 - update to 2.4.6-150300.12.13.1
corosync-qnetd - update to 2.4.6-150300.12.13.1
libcmap4 - update to 2.4.6-150300.12.13.1
corosync (Ubuntu package) - addressed in versions 3.0.3-2ubuntu2.2, 3.1.6-1ubuntu1.1, 3.1.7-1ubuntu3.1, 3.1.8-2ubuntu1.1
corosync - update to 3.1.5-2
corosync-debuginfo - update to 3.1.5-2
corosync-debugsource - update to 3.1.5-2
corosync-vqsim - update to 3.1.5-2
corosynclib - update to 3.1.5-2
corosynclib-devel - update to 3.1.5-2
corosync-epel - update to 3.1.9-0.2.el9.1
corosync - update to 3.1.9-2
corosync-vqsim - update to 3.1.9-2
corosynclib - update to 3.1.9-2
corosynclib-devel - update to 3.1.9-2
corosync - addressed in versions 3.1.9-2.fc40, 3.1.9-2.fc41, 3.1.9-3.fc42
External References
Related Security Bulletins
- Remote code execution in Corosync
- Fedora 42 update for corosync
- Fedora 41 update for corosync
- Fedora 40 update for corosync
- SUSE update for corosync
- openEuler update for corosync
- Ubuntu update for corosync
- Anolis OS update for corosync
- Fedora EPEL 9 update for corosync-epel
- Multiple vulnerabilities in IBM Security Guardium Key Lifecycle Manager
- Multiple vulnerabilities in IBM Data Virtualization on IBM Software Hub
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM OpenPages
- Multiple vulnerabilities in IBM Big SQL on IBM Cloud Pak for Data